Privacy Policy
Last updated: June 12, 2026
This policy explains what data Nexara (“we”, “us”) collects when you use the Nexara platform and website, how we use it, and the choices you have. It covers both our customers (businesses using the AI receptionist) and the people who interact with those businesses through Nexara (callers and message senders).
1. Data we collect
- Account data — name, email, password hash, business name, industry, billing status.
- Communication data — phone call audio recordings and transcripts, website chat messages, WhatsApp and SMS conversations handled by your AI receptionist, and caller phone numbers.
- Business data you store — contacts, leads, bookings, invoices, quotes, tasks, and the knowledge you give your AI (FAQs, business description, working hours).
- Usage and technical data — log data, device/browser information, and product usage events used for security, billing (e.g. call minutes), and improving the Service.
- Waitlist/contact data — email addresses and messages you submit through our forms.
2. How we use data
- To operate the Service: answering calls and messages, booking appointments, capturing leads, and showing this activity in your dashboard.
- To generate AI responses: conversation content is sent to our AI model provider (Anthropic) to produce replies. Their API does not use this data to train models.
- To bill you: usage metering (call minutes, messages) and payment processing.
- To communicate with you: transactional emails (confirmations, alerts, receipts) and product updates you can opt out of.
- To keep the Service secure and prevent abuse.
3. Call recording
Calls handled by the AI receptionist may be recorded and transcribed so business owners can review them. The business you are calling is responsible for providing any legally required recording notice. If you are a caller and want a recording deleted, contact the business directly or email us at support@nexara-ai.net.
4. Subprocessors
We use a small set of service providers to run Nexara:
- Supabase — database, authentication, and file storage
- Vercel — application hosting
- Anthropic — AI language model (conversation processing)
- Vapi / Twilio / Telnyx — telephony, phone numbers, and call handling
- Deepgram / ElevenLabs — speech-to-text and AI voice synthesis
- Meta (WhatsApp Business) / 360dialog — WhatsApp messaging
- Lemon Squeezy — payments and subscription billing (we never see your full card number)
- Resend — transactional email delivery
- Google — calendar integration, if you connect it
5. Data retention
We keep your data while your account is active. After cancellation, business data, recordings, and transcripts are deleted or anonymized within 90 days, except records we must keep for legal, billing, or security reasons. You can request earlier deletion at any time.
6. Your rights
Depending on your location (including under GDPR and similar laws), you may have the right to access, correct, export, restrict, or delete your personal data. Email support@nexara-ai.net and we will respond within 30 days. You can also delete most business data directly from your dashboard.
7. Cookies
We use essential cookies only: keeping you signed in (authentication session) and remembering product preferences. We do not run third-party advertising cookies or sell personal data.
8. Security
Data is encrypted in transit (TLS) and at rest. Access to production data is restricted, and API access is authenticated per business — your data is never visible to other customers. No system is perfectly secure; if we learn of a breach affecting your data we will notify you without undue delay.
9. Children
The Service is for businesses and is not directed at children under 16.
10. Changes
We will post any changes here and, for material changes, notify you by email or in-app before they take effect.
11. Contact
Privacy questions or requests: support@nexara-ai.net.